On Monday, Anna from an accounting office in Kielce is reviewing the tasks of a seven-person team: client names, amounts, scanned documents. Before choosing task management software, she doesn't ask about the colour of the board - she asks about the data: where will it live, and who can see it? When it comes to GDPR, your own server changes the answer to the first question, but it doesn't close off the second.

This is a description of how Task Manager works, not legal advice. Assessing your situation, documentation and decisions about data are made within your company.

Task management software and GDPR: first establish where the data lives

In Task Manager, the application files and the MySQL database sit on the client's hosting. Attachments go into the uploads/ directory on the same server, so Anna starts by checking her own hosting, rather than looking for data in an account with the software provider.

You don't need separate server infrastructure to install the program. A standard shared hosting plan with PHP 8.1+ and MySQL or MariaDB is enough; the program doesn't require Node.js, Redis or Composer. The installer runs in the browser and guides you through five screens: Requirements, Database, Administrator, Application Settings and Mail. It creates a configuration file and the database tables.

A file attached to a task isn't simply a public address in a directory. The application checks permissions when an attachment is downloaded, direct access to uploads/ is blocked, and the filenames saved on disk are randomised. Anna still has to determine who has access to the hosting panel and what her team should actually be putting into tasks in the first place. Technical details are described in installed on your own server.

Your own hosting changes where data is stored - it doesn't remove the hosting provider

Your own hosting moves the database and files from the software provider's infrastructure to hosting chosen by your company. It doesn't, however, mean the data exists solely within your own office: your hosting provider still stores the files and the database.

QuestionProgram maintained by the providerTask Manager on your own hosting
Where are the files and database located?On the service's infrastructureOn your company's hosting
Who manages the application's hosting?The service providerYour hosting provider or whoever you entrust with administration
Who organises data backups?You check the provider's terms of serviceYou establish how backups are made for your own hosting
What do you check before ending use of the program?How to recover data from the serviceThe state of your own database and files on the hosting

This is a comparison of storage models, not an evaluation of any specific cloud program. On Tuesday, Anna might ask whoever looks after the hosting to point out where the database backup and the attachments directory are. The mere fact that the server is "hers" doesn't yet mean a backup is actually being made and can be restored.

The browser doesn't need to connect to external servers

The browser loads the Task Manager interface from the server where the application was installed. This applies to libraries, fonts, icons and placeholder avatars, including on the login screen and in the installer.

There's no loading of interface elements from a CDN - that is, an external server delivering the page's files - or from Google Fonts. When someone doesn't add a profile picture, the browser draws a circle with their initials. The application also works on a network without internet access.

Don't mistake this for a promise that no connection ever goes out. The server can connect to the configured AI provider and the IMAP/SMTP mail server; it also contacts the licence panel when checking for updates and licence status. If you need a list of included libraries, you'll find it along with their licences in the LICENCJE-BIBLIOTEK.md file in the application directory.

Once AI is switched on, some data goes to the model provider

Once AI is switched on, Task Manager sends the content of the query and the context needed for the response to the chosen provider - which is why the statement "data never leaves the server" would be untrue. With AI switched off, Task Manager doesn't send any requests to the model provider.

In Settings, under the AI tab, the administrator chooses a provider, enters their own API key and selects a model - the application fetches the list of models from the provider's account. OpenAI, Anthropic, Google and xAI are available. The company pays the provider directly for using the model, with no mark-up from Task Manager. AI can be switched on separately for tasks, chats and the AI Assistant window. The Assistant only sees material that the person asking has access to, and Mail is disabled by default as a source of AI knowledge.

The AI Settings window with a masked API key and selected model
The administrator chooses the provider and model and supplies their own API key

On Wednesday, Anna is considering connecting a model, but first checks whether customer data might appear in the team's questions. She could also leave AI switched off - Task Manager works without it. You'll find a detailed description of the flow in the article what reaches the AI provider.

The administrator manages access, but doesn't read everything

The Task Manager administrator sees and manages Workspaces and Tasks, but doesn't have visibility into all users' private content. Mail, unshared Notes and AI Assistant conversation Threads remain private even from them.

The program has two global roles: administrator and user, who sees their own Workspaces. Within each Workspace, you separately set the Workspace administrator and permissions for adding Tasks and Chats. Separate permissions cover, among other things, AI in Tasks, AI in Chats, the AI Assistant window and Mail; without the permission, the feature disappears from the interface. Assigning a private Note to a Workspace is only a label, not sharing it with the team. Similarly, linking a Mail Thread to a Task creates a navigation shortcut, not access to the email's content.

The Users window with a person assigned to specific Workspaces and permissions
You set Workspace assignment and permissions for Tasks and Chats separately

On Friday, Anna adds a new accountant to a single Workspace, rather than assuming she should see all the business of the seven-person team. The invited person sets their own password after receiving an email. When an employee leaves, Anna can deactivate them: the data remains, and the licence seat is freed up. The way access is divided is shown in more detail in the article on who sees tasks and how roles work.

Old logs and old tasks are deleted in two different ways

Cleaning up technical logs removes log files and expired sessions, but doesn't touch Tasks, Chats, Messages or attachments. Permanently deleting old content is a separate, manual operation that removes actual user data and cannot be undone.

By default, logs are cleaned once a day when someone uses the application. Login attempt logs older than 30 days disappear along with expired sessions. The application also removes the n8n event log older than 90 days and processed n8n queue entries older than 30 days. n8n is a tool for connecting applications into automated processes. The administrator can also use the "Clean up old logs now" button.

In Settings, under the Advanced tab, you can separately choose permanent deletion of archived Tasks, closed Tasks, or just old Messages. Available thresholds are 30, 90, 180 and 365 days. The application first shows the number of items and the estimated space freed, then requires you to re-type a random 8-character code. Make a backup of the database before taking this step.

The following Monday, Anna selects closed Tasks older than 365 days and first checks the preview of items to be deleted. She doesn't treat the log cleanup button as a way to delete customer data. Both mechanisms are described in the data cleaning guide.

Activity History belongs to the person who creates it

Activity History in Task Manager is the account owner's private log, not a view for overseeing the team. The administrator cannot view it.

The log can record, for example, creating a Task, changing a status, adding a file, and sessions of viewing a Task, Chat or Note. It stores links and titles, not the content of messages, notes or emails; it also doesn't record searches or automation actions. Entries older than 90 days disappear automatically.

Each person can turn off recording in their Profile, clear their history, or specify a Workspace, Task, Chat or Note for which their activity shouldn't be recorded. Suggestions based on history are calculated by the application itself, without sending data to an AI provider. There is, however, an important caveat: when you use the AI Assistant, a summary of the history - not the raw log - is included in its request to the configured model provider.

Your own server won't make data decisions for you

Installing on your own hosting won't choose your data, the people with access, or how long content is retained, for you. Nor will it replace company documentation, arrangements with your hosting provider, and an assessment of whether your adopted way of working suits your situation.

Take care of database and attachment backups and check for available updates. The administrator triggers an update in Settings: first "Download", after a warning about backing up the database and the uploads/ directory, then "Install". HTTPS is always recommended and is required to install the program as an app on a device. Sensitive data, such as API keys, SMTP passwords and message content, is encrypted in the database; this does not mean the entire database is encrypted. The Pro variant adds AES-256 encryption.

Task Manager's licence is perpetual and includes 12 months of updates, after which renewal is optional. Not renewing updates doesn't block work on the version you own. The application switches to read-only mode if there's no licence key, an invalid key, or a fixed-term key has expired. The rules are described on the perpetual licence page.

Tomorrow, write down which customer data should go into Tasks, who should see it, and who is responsible for the database and attachment backup. Only with that note in hand should you check the Workspace and permission setup in the Demo.

Frequently asked questions

Where is data from task management software stored on your own server?

Task Manager's data is kept on your company's hosting: Tasks in a MySQL database, and attachments in the uploads/ directory. The hosting company still stores these files and the database.

Does Task Manager work without an internet connection and without connections to external services?

Task Manager works on a network without internet access, and its browser interface does not load elements from external servers. However, configured AI and Mail services require outgoing connections, and the server connects to the licence panel when checking the licence status and updates; installing on your own hosting alone does not determine your company's GDPR compliance.

Does data leave my server once the AI Assistant is switched on?

Yes - the content of the query and the context needed for the response are sent to the selected model provider. With AI switched off, Task Manager does not send any requests to the model provider.

Can the Task Manager administrator see all employee activity?

No - Mail, unshared Notes, AI Assistant threads and Activity History remain private, even from the administrator. The administrator does, however, manage access to workspaces and user permissions.

Does your own hosting mean you don't need to worry about GDPR?

No - your own hosting changes where data is stored, but it does not make decisions for your company about access, backups, documentation and retention periods. This article describes how the program works and does not replace a legal assessment of your situation.

Sources

  1. Task Manager, Installed on your own server
  2. Task Manager, Frequently asked questions
  3. Task Manager, Your model, your key
  4. Task Manager, Users and Roles
  5. Task Manager, Data Cleaning
  6. Task Manager, Activity History
  7. Task Manager, Perpetual licence

The Task Manager Team - we write about teamwork, AI in business and keeping tasks organised, using examples from Task Manager, software installed on your own server. Task Manager has been developed by Blue Creation Group (Piotr Łącz) since 2013 and is used by organisations including Neonet, the Military University of Technology and Polpharma - read customer reviews. We check our articles against the user guide and the latest version of the software.